New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
FS#1083 - ar71xx Kernel 4.9 PPTP Passthrough not working #6794
Comments
chandlerding: Install kmod-nf-nathelper-extra and try again? |
nouman8: kmod-nf-nathelper-extra is installed |
nouman8: if anyone else could test this behavior on their ar71xx device with 4.9 kernel ?? |
maabo: yes, me.
I have tried to compile the image from trunk sources, then tried the image generator, but it is always the same: the module nf_nat_pptp is loaded, but not working with 4.9.65 kernel I found that in kernel logs this message appeared: I attached some more detailed infos to this post. If You need some other traces to investigate, dont hasitate to contact me. Martin |
maabo: And I confirm, that after building image from trunk source with KERNEL_PATCHVER:=4.4 the problem disappeared. |
arjendekorte: This is not surprising. The default for automatic loading of connection tracking helpers was changed in kernel-4.7. So with kernel-4.4, the pptp helper will be loaded automatically when PPTP traffic is seen, but for kernel-4.9 you'll have to do that explicitly. Adding something along the lines
should load the connection tracker helper in your firewall. You could append this line to your /etc/firewall.user for instance to load it automatically. |
maabo: Hello and thank You for clearing it out! I decided to keep the older kernel and wait some additional time before updating to 4.9, until all these issues with conntrack helpers will be tested, better documented and user-friendly handled. I understand, that the automatic loading could be a security issue. //P.S.: IMHO solution to achieve better security but keep the user friendly management could be splitting the nathelpers-extra into more specific nathelper-pptp , nathelper-sip, etc and add the iptables record automatically within installation without forcing users to do it manually. OR make Luci capable to handle the conntrack config.// |
nouman8:
today i compiled for my TP-Link mr3420 v2 with Kerenl 4.9 by simply changing the KERNEL_PATCHVER:=4.4 to KERNEL_PATCHVER:=4.9 in target/linux/ar71xx/Makefile , everything works good so far except i am not able to connect to the VPN which was working good previously with 4.4 kernel compiled lede a week back.
The text was updated successfully, but these errors were encountered: